Install
Google ADK is a peer dependency:
Quick Start
If the grant token doesn’t include the required scope, create_grantex_tool raises a PermissionError immediately.
API Reference
Creates a plain function with the correct __name__ and __doc__ for ADK tool discovery. Before execution it verifies the token against the configured JWKS endpoint and enforces scopes from the verified claims.
Returns unverified scopes decoded from a grant token. Use this only for display or debugging, never for authorization.
decode_jwt_payload(token)
Decodes the payload of a JWT without verifying the signature.
Requirements
- Python 3.9+
grantex >= 0.1.0
google-adk >= 0.2.0 (peer dependency)
Ownership
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Current Authority and Human Identity
Use the exact integration version and minimum primary SDK in Release Status.
Per-invocation issuer authority and trusted principal/agent binding are opt-in.
Configure the callback with the trusted issuer and derive identity from the host’s
authenticated session; signature and scope checks alone do not prove current
revocation or human consent. See SDK execution authority
for configuration, denial behavior and manifest/decision/caps boundaries.Last modified on September 29, 2026